PT-2025-13599 · Unknown · Netty Quic Codec

Published

2025-03-28

·

Updated

2025-03-31

·

CVE-2025-29908

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Netty QUIC codec versions prior to 0.0.71.Final
Description A hash collision vulnerability in the Netty QUIC codec allows remote attackers to cause a considerable CPU load on the server by initiating connections with colliding Source Connection IDs (SCIDs), resulting in a Hash DoS attack.
Recommendations For versions prior to 0.0.71.Final, update to version 0.0.71.Final to resolve the issue. As a temporary workaround, consider restricting access to the quiche module or limiting the number of connections to minimize the risk of exploitation.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-29908
GHSA-HQQC-JR88-P6X2

Affected Products

Netty Quic Codec